QuestionQ21

Threat Hunting Processes

The SOC team receives an alert for a user sign-in from an unusual country. After reviewing the SIEM logs, the team confirms that the user never signed in from that country. The incident is reported to the IT administrator, who resets the user’s password.

Which threat-hunting phase was used initially?

Explanation

A threat hunt starts with a hypothesis about potentially malicious activity. An unusual-country sign-in alert supplies the suspicion that the account may have been accessed from that location; reviewing SIEM data validates or disproves that hypothesis. Password reset belongs to the subsequent response activity.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!